Understanding and avoiding malvertizing attacks

Online advertisements can be an annoying interruption to our normal surfing behavior. However, they are often necessary because they serve as the main source of funding for the otherwise free websites we use every day. Have you ever wondered how those ads end up on your screen? Well, there’s a fascinating supply chain behind the ads, and it’s interesting to pick it apart.

Normally, a website that displays advertisements does not manually select the specific advertisements displayed on its platform. Instead, it chooses ad categories to block, allocates ad space, and then serves the ads that the ad provider serves. Advertising providers are responsible for finding advertisers and websites to display their advertisements. But what if those advertisers aren’t legitimate? What if they are threat actors or scammers looking to lure potential victims with seemingly legitimate software or help fix your computer? This malicious use of advertising is called malvertizing.